8000 fix(weaver): vulnerability GHSA-29mw-wpgm-hmr9 · Issue #3859 · hyperledger-cacti/cacti · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

fix(weaver): vulnerability GHSA-29mw-wpgm-hmr9 #3859

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
jagpreetsinghsasan opened this issue Apr 15, 2025 · 0 comments
Open

fix(weaver): vulnerability GHSA-29mw-wpgm-hmr9 #3859

jagpreetsinghsasan opened this issue Apr 15, 2025 · 0 comments
Labels
bug Something isn't working Security Related to existing or potential security vulnerabilities Weaver Tasks related to the future of Cactus & Weaver together.

Comments

@jagpreetsinghsasan
Copy link
Contributor
jagpreetsinghsasan commented Apr 15, 2025

Describe the bug
GHSA-29mw-wpgm-hmr9
Moderate severity

Image

gluegun uses lodash.trim, loadash.trimend versions with the above mentioned vulnerability

└─ gluegun@npm:5.1.6
└─ lodash.trim@npm:4.5.1 (via npm:^4.5.1)

└─ gluegun@npm:5.1.6
└─ lodash.trimend@npm:4.5.1 (via npm:^4.5.1)

And are present in our packages here,
├─ @hyperledger/cacti-weaver-besu-cli@workspace:weaver/samples/besu/besu-cli
│ └─ gluegun@npm:5.1.6 (via npm:5.1.6)

└─ @hyperledger/cacti-weaver-fabric-cli@workspace:weaver/samples/fabric/fabric-cli
└─ gluegun@npm:5.1.6 (via npm:5.1.6)

Steps to reproduce
yarn why lodash.trim
yarn why lodash.trimend
yarn why gluegun

@VRamakrishna @sandeepnRES

@jagpreetsinghsasan jagpreetsinghsasan added bug Something isn't working Weaver Tasks related to the future of Cactus & Weaver together. Security Related to existing or potential security vulnerabilities labels Apr 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Security Related to existing or potential security vulnerabilities Weaver Tasks related to the future of Cactus & Weaver together.
Projects
None yet
Development

No branches or pull requests

1 participant
0